## Bypass Shitty Price Tag - Jizzedtothis.com

# In the Source code

Searching for the username used in the URL path, we find this url:

![](/screen1.png) 

Going to this URL, we download all the images!

### NOTE: These images were already available for download, you could've just selected them 1 by 1 and downloaded them that way but we're lazy.

# Bypassing "Members-only photos"

Member's only on this site requires us to be signed in or whatever but I don't like the idea of passing my info to a Wordpress account plus finding bypasses is fun.

In the last photo, the URL has an ID parameter which interests me, if we could grab the ID of this "member's only" folder, then we can probably grab all the photos.

*https://jizzedtothis.com/photos/USERNAME_HERE/?envira-downloads-gallery-id=ID-HERE&envira-downloads-gallery-image=all*

After searching for "id=", we find this:

![](screen2.png) 

Throwing that in our URL to make this:

*https://jizzedtothis.com/photos/doublecurvy-annacurvy/?envira-downloads-gallery-id=431999&envira-downloads-gallery-image=all*

Navigating to that URL...

![](screen3.png) 

Boom! zip file containing all the imgs that were under the "member's only dir"


https://jizzedtothis.com/photos/martina-prinx-members/?envira-downloads-gallery-id=419097&envira-downloads-gallery-image=all


### NOTE: For video files in non-members content (EX: here - https://jizzedtothis.com/photos/ellie-marie/), these guys use .mp4s, which can be searched in the view-source page & downloaded
 
As you can see, searching for the .mp4 extension, we get a ton of URLs, one is highlighted:

![](screen4.png) 

Navigating to this URL, we see it is indeed the video. Unfortunately this doesn't work for member's only videos as far as I know since they're hosted using a VPS

We can also do a *wget* on the video to save it locally!